Zero trust data access (ZTDA) based on security posture tags
Security posture tags are calculated from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices. A request for access including a name of a data file is received. A security posture tag associated with the data file receive. One or more zero trust data access (ZTDA) network policies associated with data file itself is applied as corresponding to the request and/or the data of the security posture tag are applied. Access to the data file of the request is then provided, subject to application of the one or more ZTDA network policies identified as corresponding to the request.
1 . A computer-implemented method in a network security device, on a data communication network, for providing zero trust data access (ZTDA) based on security posture tags associated with data files, the method comprising:
calculating security posture tags from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices;
receiving a request for access including a name of a data file, wherein the request has established secured network access, and wherein the request does not include a specific location of the data file;
receiving a security posture tag associated with the data file and identifying ZTDA network policies that are relevant;
applying the one or more ZTDA network policies identified as corresponding to the request and/or the data of the security posture tag;
applying the one or more ZTDA policies against the security posture tag at a security agent of a network device storing the data file;
receiving the results from the security agent; and
providing access to the data file of the request, subject to application of the one or more ZTDA network policies identified as corresponding to the request.
2 . The method of claim 1 , further comprising:
identifying one or more zero trust network access (ZTNA) network policies corresponding to the request; and
providing access to a network device storing the data file of the request subject to application of the one or more ZTNA network policies identified as corresponding to the request.
3 . The method of claim 1 , wherein the network security device comprises a firewall.
4 . The method of claim 1 , wherein the network security device comprises an endpoint management system (EMS) server.
5 . The method of claim 1 , wherein the information for the security posture updates are initiated by plurality of security agents upon identifying an internal operation relevant to network security.
6 . The method of claim 1 , wherein the ZTDA security posture tags are stored separately from corresponding data files.
7 . The method of claim 1 , the request comprise a command related to the data file, selected from one of: move, copy, rename and delete.
8 . The method of claim 1 , wherein the request is allowed by the network access policies and not allowed by a data access policies.
9 . The method of claim 1 , wherein the request is allowed by the data access policies and not allowed by the network access policies.
10 . A non-transitory computer-readable medium in a network security device, on a data communication network, storing code that when executed, performing a method for providing zero trust data access (ZTDA) based on security posture tags associated with data files, the method comprising:
calculating security posture tags from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices;
receiving a request for access including a name of a data file, wherein the request has established secured network access, and wherein the request does not include a specific location of the data file;
receiving a security posture tag associated with the data file and identifying ZTDA network policies that are relevant;
applying one or more ZTDA network policies identified as corresponding to the request and/or the data of the security posture tag;
applying the one or more ZTDA policies against the security posture tag at a security agent of a network device storing the data file; and
receiving the results from the security agent; and
providing access to the data file of the request, subject to application of the one or more ZTDA network policies identified as corresponding to the request.
11 . The method of claim 10 , further comprising:
identifying one or more zero trust network access (ZTNA) network policies corresponding to the request; and
providing access to a network device storing the data file of the request subject to application of the one or more ZTNA network policies identified as corresponding to the request.
12 . A network security device, on a data communication network, for providing zero trust data access (ZTDA) based on security posture tags associated with data files, the network security device comprising:
a processor;
a network interface communicatively coupled to the processor and to a data communication network; and
a memory, communicatively coupled to the processor and storing:
a security posture tag module to calculate security posture tags from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices;
an access request queue to receive a request for access including a name of a data file, wherein the request has established secured network access, and wherein the request does not include a specific location of the data file;
a ZTDA module to receive a security posture tag associated with the data file and identifying ZTDA network policies that are relevant,
wherein the ZTDA module applies one or more ZTDA network policies identified as corresponding to the request and/or the data of the security posture tag;
applies the one or more ZTDA network policies against the security posture tag at a security agent of a network device storing the data file; and
receives the results from the security agent; and
a file database interface to provide access to the data file of the request, subject to application of the one or more ZTDA network policies identified as corresponding to the request.
13 . The network security device of claim 12 , further comprising:
identifying one or more zero trust network access (ZTNA) network policies corresponding to the request; and
providing access to a network device storing the data file of the request subject to application of the one or more ZTNA network policies identified as corresponding to the request.